Help Needed: Persistent "lazerpenguin.com" Proxy Hijacking Browser

MetroMaverick

Newbie
Joined
Jun 4, 2025
Messages
12
Reaction score
3
Hey BHW community,
I'm facing a stubborn browser issue on my macOS, and I've hit a wall after trying all the standard solutions. I'm hoping someone here might have seen this before or can offer some advanced guidance.

The Problem:
For the last few days, my Chrome browser has been constantly interrupted by a proxy authentication pop-up. The pop-up asks for a username/password for a proxy server that changes slightly but always uses the lazerpenguin.com domain (e.g., ip-208-115-233-XX.lazerpenguin.com:8080).

What I've Already Done (With No Success):

I've spent a significant amount of time trying to troubleshoot this myself. Here is a complete list of everything I've tried:

  1. System Settings: Checked macOS System Settings > Network > Proxies. Everything is unchecked and clean.
  2. Configuration Profiles: Checked System Settings > Privacy & Security > Profiles. The "Profiles" section doesn't exist, which means no profiles are installed.
  3. Security Scans:

  • Ran a full scan with CleanMyMac X. It found nothing.
  • Ran a full scan with Malwarebytes for Mac (Premium). It also found 0 threats and 0 PUPs.
  1. Browser Troubleshooting:
    • Completely reset Google Chrome settings to default.
    • Manually checked and removed all browser extensions. I even suspected a fake TunnelBear VPN extension, removed it, but the problem persists even with no extensions installed.
    • Tried browsing in a brand new, clean Chrome user profile without signing into any Google account. The issue still appears.
    • Safari Test: The pop-up seems to be happening only in Chrome, not in Safari.
Despite all these steps, the lazerpenguin proxy pop-up keeps coming back. It feels like something is embedded deep within Chrome or the system that the security tools can't detect.

My Questions:

  • Has anyone ever encountered the lazerpenguin.com domain before? Is it a known adware/malware?
  • Are there any deeper, manual removal steps I can take? Perhaps checking specific system library files or advanced Chrome flags/policies (chrome://policy)?
  • Could this be something other than malware that I'm completely missing?
I'm truly at my wits' end and would be extremely grateful for any insights or suggestions from the experienced members here.

Thanks in advance for your time and help!

1752389089895.png
 
Have you try going to check your chrome settings?
Go to settings under your chrome, open your computer proxy setting (you can just use the search box)
Put off "use a proxy server" and you should be good.
Hey BHW community,
I'm facing a stubborn browser issue on my macOS, and I've hit a wall after trying all the standard solutions. I'm hoping someone here might have seen this before or can offer some advanced guidance.

The Problem:
For the last few days, my Chrome browser has been constantly interrupted by a proxy authentication pop-up. The pop-up asks for a username/password for a proxy server that changes slightly but always uses the lazerpenguin.com domain (e.g., ip-208-115-233-XX.lazerpenguin.com:8080).

What I've Already Done (With No Success):

I've spent a significant amount of time trying to troubleshoot this myself. Here is a complete list of everything I've tried:

  1. System Settings: Checked macOS System Settings > Network > Proxies. Everything is unchecked and clean.
  2. Configuration Profiles: Checked System Settings > Privacy & Security > Profiles. The "Profiles" section doesn't exist, which means no profiles are installed.
  3. Security Scans:

  • Ran a full scan with CleanMyMac X. It found nothing.
  • Ran a full scan with Malwarebytes for Mac (Premium). It also found 0 threats and 0 PUPs.
  1. Browser Troubleshooting:
    • Completely reset Google Chrome settings to default.
    • Manually checked and removed all browser extensions. I even suspected a fake TunnelBear VPN extension, removed it, but the problem persists even with no extensions installed.
    • Tried browsing in a brand new, clean Chrome user profile without signing into any Google account. The issue still appears.
    • Safari Test: The pop-up seems to be happening only in Chrome, not in Safari.
Despite all these steps, the lazerpenguin proxy pop-up keeps coming back. It feels like something is embedded deep within Chrome or the system that the security tools can't detect.

My Questions:

  • Has anyone ever encountered the lazerpenguin.com domain before? Is it a known adware/malware?
  • Are there any deeper, manual removal steps I can take? Perhaps checking specific system library files or advanced Chrome flags/policies (chrome://policy)?
  • Could this be something other than malware that I'm completely missing?
I'm truly at my wits' end and would be extremely grateful for any insights or suggestions from the experienced members here.

Thanks in advance for your time and help!

View attachment 458406
 
It's a bit late, but LazerPenguin is a domain used by TunnelBear VPN. So, if you're using McAfee VPN (which uses TunnelBear) or TunnelBear directly, this is a problem caused by that. I don't know why, but I was encountering this even when the VPN wasn't active, and deleting it fixed the problem.
 
that makes sense. TunnelBear and a few McAfee-branded VPNs use lazerpenguin as part of their proxy routing. Even if the app looks inactive, background services can still set proxy rules in Chrome. Removing or fully uninstalling the VPN and restarting usually clears it up.
 
Looks like a persistent Chrome-level proxy hijack. Check chrome://policy for any forced proxy or extension policies — corporate or rogue configs sometimes sneak in there. Also, inspect /Library/LaunchAgents, /Library/LaunchDaemons, and ~/Library/LaunchAgents for suspicious .plist files that could auto-inject a proxy. If all else fails, a full Chrome reinstall after removing those files usually clears it.
 
Back
Top